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Abstract 



Shor's and Grover's famous quantum algorithms for factoring and searching show that 
quantum computers can solve certain computational problems significantly faster than any 
classical computer. We discuss here what quantum computers cannot do, and specifically how 
to prove limits on their computational power. We cover the main known techniques for proving 
lower bounds, and exemplify and compare the methods. 

1 Introduction 

The very first issue of the Journal of the ACM was published in January 1954. It was the first 
journal devoted to computer science. For its 50th anniversary volume, published in January 2003, 
editors-in-chief Joseph Y. Halpern asked winners of the Turing Award and the Nevanlinna Prize 
to discuss up to three problems that they thought would be major problems for computer science 
in the next 50 years. Nevanlinna Prize winner Leslie G. Valiant [ Val03 1 describes three problems, 
the first of which is on physically realizable models for computation and formalizes the setting 
by defining: "We therefore call our class PhP, the class of physically constructible polynomial 
resource computers." He then formulates the problem by: "[t]o phrase a single question, the full 
characterization of PhP," and argues that "this single question appears at this time to be scientifi- 
cally the most fundamental in computer science." 

On January 26, this year, Nobel Laureate David Gross gave a CERN Colloquium presenta- 
tion on "The future of physics" HGro 05 1 . He discusses "25 questions that might guide physics, in 
the broadest sense, over the next 25 years," and includes as questions 15 and 16 "Complexity" and 
"Quantum Computing." In July, this year, the Science magazine celebrated its 125th anniversary by 
"explor[ing] 125 big questions that face scientific enquiry over the next quarter-century" I S ei05H . 
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Among the top 25, is the question of "What are the limits of conventional computing?" Charles 
Seife writes: "[T]here is a realm beyond the classical computer: the quantum," and he discusses 
the issue of determining "what quantum-mechanical properties make quantum computers so pow- 
erful." 

In this issue of the Bulletin of the EATCS, we would like to offer an introduction to the topic 
of studying limitations on the power of quantum computers. Can quantum computers really be 
more powerful than traditional computers? What can quantum computers not do? What proof 
techniques are used for proving bounds on the computational power of quantum computers? It 
is a highly active area of research and flourishing with profound and beautiful theorems. Though 
deep, it is fortunately also an accessible area, based on basic principles and simple concepts, and 
one that does not require specialized prior knowledge. One aim of this paper is to show this by 
providing a fairly complete introduction to the two most successful methods for proving lower 
bounds on quantum computations, the adversary method and the polynomial method. Our survey 
is biased towards the adversary method since it is likely the least familiar method and it yields very 
strong lower bounds. This paper is meant to be supplemented by the excellent survey of Buhrman 
and de Wolf [BW02| on decision tree complexities, published in 2002 in the journal Theoretical 
Computer Science. 

We demonstrate the methods on a running example, and for this, we use one of the most basic 
algorithmic questions one may think of: that of searching an ordered set. Can one implement 
ordered searching significantly faster on a quantum computer than applying a standard 6 (log N) 
binary search algorithm? 

The rest of the paper is organized as follows. We motivate and define our models of compu- 
tation in the next section. We then discuss very basic principles used in proving quantum lower 
bounds in Section|3]and use them to establish our first lower-bound method, the adversary method, 
in Section|4| We discuss how to apply the method in Section|5l and its limitations in Section|6l We 
then give an introduction to the second method, the polynomial method, in Section|7J We compare 
the two methods in Section[5]and give a few final remarks in Section|5| 

We have aimed at limiting prior knowledge on quantum computing to a bare minimum. Sen- 
tences and paragraphs with kets and bras (|this is aket) and (this is abra|) can either safely be 
skipped, or substituted with column- vectors and row-vectors, respectively. 

2 Quantum query complexity 

Many quantum algorithms are developed for the so-called oracle model in which the input is given 
as an oracle so that the only knowledge we can gain about the input is in asking queries to the 
oracle. The input is a finite bitstring x E {0, 1}^ of some length N, where x = X\X2 ■ ■ ■ %n- The 
goal is to compute some function F : {0, 1}^ — > {0, l} m of the input x. Some of the functions we 
consider are boolean, some not. We use the shorthand notation [N] = {1,2,..., iV}. 

As our measure of complexity, we use the query complexity. The query complexity of an 
algorithm A computing a function F is the number of queries used by A. The query complexity of 
F is the minimum query complexity of any algorithm computing F. We are interested in proving 
lower bounds on the query complexity of specific functions and consider methods for computing 
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such lower bounds. 

An alternative measure of complexity would be to use the time complexity which counts the 
number of basic operations used by an algorithm. The time complexity is always at least as large 
as the query complexity since each query takes one unit step, and thus a lower bound on the query 
complexity is also a lower bound on the time complexity. For most existing quantum algorithms, 
including Grover's algorithm [Gro96|, the time complexity is within poly-logarithmic factors of 
the query complexity. A notorious exception is the so-called Hidden Subgroup Problem which has 
polynomial query complexity [EHK04|, yet polynomial time algorithms are known only for some 
instances of the problem. 

The oracle model is called decision trees in the classical setting. A classical query consists of 
an index i E [N], and the answer of the bit Xj. There is a natural way of modelling a query so that 
it is reversible. The input is a pair (i, b), where i E [N] is an index and b E {0, 1} a bit. The output 
is the pair (z, b © Xi), where the bit b is flipped if x,; = 1. There are (at least) two natural ways of 
generalizing a query to the quantum setting, in which we require all operations to be unitary. The 
first way is to consider a quantum query as a unitary operator that takes two inputs \i)\b), where 
i E [N] and b E {0, 1}, and outputs \i)\b ffi £;). The oracle is then simply just a linear extension of 
the reversible query given above. We extend the definition of the oracle so that we can simulate a 
non-query, and we allow it to take some arbitrary ancilla state | z) with z > as part of the input 
and that is acted upon trivially, 



The ancilla \z) contains any additional information currently part of the quantum state that is not 
involved in the query. 

The second way is to consider a quantum query as a unitary operator O x that takes only the one 
input \i) and outputs (— i) Xi where i E [N]. We say that the oracle is "computed in the phases" 
by O x . Both operators 0^. and O x square to the identity, i.e., they are their own inverses, and thus 
unitary. The two operators are equivalent in that one query to either oracle can be simulated by a 
superposition query to the other oracle preceeded and followed by a basis change. Though the first 
way is possibly the more intuitive, we shall adapt the second way as it is very convenient when 
proving lower bounds. Again, we extend the definition of the oracle O x so that it also embodies a 
non-query, and we allow it to take some arbitrary ancilla state | z) that is not acted upon, 



We may think of one query as a one-round exchange of information between two parties, the 
algorithm and the oracle. In the classical setting, the algorithm sends an index i E [N] to the 
oracle, and the oracle responds with one bit of information, namely x^ In the quantum setting, the 
algorithm sends the log 2 (iV) qubits \i) to the oracle O x , and the oracle responds with (— l) Xi \i). 
The algorithm and oracle thus exchange a total number of 2 log 2 (iV) qubits, and thus, a quantum 
query to O x can convey up to 2 log 2 (iV) classical bits of information about the oracle by Holevo's 
theorem BHol73HCD + 98t and superdense coding BBW92II . 




i, b;z) if i = or Xi = 

i,b®l;z) if % E [N] and Xj = 1. 



(1) 




(2) 
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Information theoretically, a function F : {0,1}^ — > {0, l} 1 ^^) that outputs at most 
0(log 2 (iV)) bits, can potentially be solved by a constant number of queries to the oracle. An 
example of such a problem is the Deutsch-Jozsa problem [DJ92|, which is to distinguish balanced 
boolean functions from constant functions. (A function F is constant if F(x) = F(y) for all inputs 
x, y, and it is balanced if it is not constant and |F _1 (F(a;))| = \F~ 1 (F(y))\ for all inputs x, y.) 

A quantum algorithm in the oracle model starts in a state that is independent of the oracle. For 
convenience, we choose the state |0) in which all qubits are initialized to 0. It then evolves by 
applying arbitrary unitary operators U to the system, alternated with queries O x to the oracle x, 
followed by a conclusive measurement of the final state, the outcome of which is the result of the 
computation. In symbols, a quantum algorithm A that uses T queries, computes the final state 

|Vj) = U T O ai U r _ 1 ...U 1 O a! Uo|0) (3) 

which is then measured. If the algorithm computes some function F : {0, 1}^ — > {0, l} m , we 
measure the m leftmost bit of the final state producing some outcome w. The success prob- 
ability p x of A on input x G {0, 1}^ is the probability that w = F(x). For complete functions 
F : {0,1}^ — > {0, l} m , we define the success probability of A as the minimum of p x over all 
x G {0, 1}^. For partial functions F : S — > {0, l} m , where S C {0, 1}^, we take the mini- 
mum over S only. A quantum algorithm A has error at most e if the success probability of A is 
at least 1 — e. Let Q e (F) denote the minimum query complexity of any quantum algorithm that 
computes F with two-sided error at most e, and as common, let Q2(F) = Qi/s(F) denote the 
two-sided bounded error complexity with e = 1/3. 

As our running example, we use the well-known ordered searching problem. In the oracle 
model, the input to ordered searching is an A r -bit string x = (xi, . . . , xn). We are promised that 
%i < for all 1 < % < N and that x^ = 1, and the goal is to find the leftmost 1, i.e., the index 
i G [N] for which X{ — 1 and no index j < i exists with Xj = 1. 

Given: An A^-bit string x = (a?i, x 2 , ■ ■ ■ , xn) given as an oracle. 

Promise: Xi < Xi+\ for 1 < i < N and xn = 1- 

Output: Index i such that x - L = 1 and either = or % = 1. 

The classical query complexity of ordered searching is [log 2 (A / ")] and is achieved by standard 
binary searching. The quantum query complexity is at most 0.45 log 2 N, due to the work of high 
school student M. B. Jacokes in collaboration with Landahl and Brookes [ JLB05 1 (See also [FGGS , 
IHNS 02I). Using the adversary method, we show that their algorithm is within a factor of about 
two of being optimal. 

3 Distinguishing hard inputs 

The first quantum lower bound using adversary arguments was given by Bennett, Bernstein, Bras- 
sard, and Vazirani in [BB + 97|. They show that any quantum query algorithm can be sensitive 
to at most quadratically many oracle bits, which implies a lower bound of f2(v7V) for Graver's 
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problem [Gro96| and thus proves that Grover's 0(y/~N) algorithm is optimal. Grover's problem 
is a search problem in which we are given an iV-bit string x E {0, 1} W as an oracle, and the 
goal is to find an index i for which x» = 1, provided one exists. Interestingly, the lower bound 
of Bennett et al. was proved in 1994, well before Grover defined his search problem. In 2000, 
Ambainis [Amb02| found an important generalization of the method and coined it "adversary ar- 
guments." 

A constructive interpretation of basic adversary arguments is in terms of distinguishability . We 
will thus not be concerned with computing the function F, but merely interested in distinguishing 
oracles. Consider some algorithm A that computes some function F in the oracle model, and 
consider two inputs x,y E {0, 1}^ for which F(x) ^ F(y). Since A computes F, it must in 
particular be capable of distinguishing between oracle x and oracle y. For a given problem we try 
to identify pairs of oracles that are hard to distinguish. If we can identify hard input pairs, we may 
derive a good lower bound. However, a caveat is that using only the very hardest input pairs does 
not yield good lower bounds for some problems, and we are thus naturally led to also consider less 
hard input pairs. A remedy is to use weights that capture the hardness of distinguishing each pair 
of oracles, and to do so, we define a matrix T of dimension 2 N x 2 N that takes non-negative real 
values, 



We require that T is symmetric and that T[x, y] = whenever F(x) = F(y). We say that T is a 
spectral adversary matrix for F if it satisfies these two conditions. The symmetry condition on T 
states that we are concerned with distinguishing between any two inputs x, y. We are not concerned 
with distinguishing x from y, nor distinguishing y from x. We discuss this subtlety further in 
Section |5] below when considering alternative definitions of weighted adversary arguments. The 
spectral adversary matrix T allows us to capture both total and partial functions, as well as non- 
boolean functions. Since we are only concerned with distinguishability, once we have specified 
the entries of T, we may safely ignore the underlying function F. 

Weighted adversary arguments were first used by H0yer, Neerbek, and Shi in [HNS02] to 
prove a lower bound of fi(log N) for ordered searching and Q(N log N) for sorting. Barnum and 
Saks [BS04| used weighted adversary arguments to prove a lower bound of Q(y/~N) for read-once 
formulae, and introduced the notion T that we adapt here. Barnum, Saks, and Szegedy extended 
their work in [BSS03 1 and derived a general lower bound on the query complexity of F in terms 
of spectral properties of matrix T. Their lower bound has a very elegant and short formulation, a 
basic proof, and captures important properties of adversary methods, and we shall thus adapt much 
of their terminology. 

As discussed above, the key to prove a good lower bound is to pick a good adversary matrix T. 
For our running example of ordered searching, which is a partial non-boolean function, we use the 
following weights. 

Example: Ordered Seaching 1 The weight on the pair (x, y) is the inverse of the Hamming dis- 
tance of x and y, 



r : {0, 1}" x {0, 1} 



N 




(4) 




if x and y are valid and distinct inputs to F 
otherwise. 



(5) 
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The larger the Hamming distance between x and y, the easier it is to distinguish them, and the 
smaller weight is assigned to the pair. 

We have to choose how to measure distinguishability. The possibly simplest measure is to 
use inner products. Two quantum states are distinguishable with certainty if and only if they are 
orthogonal, and they can be distinguished with high probability if and only if their inner product 
has small absolute value. 

Fact 1 Suppose we are given one of two known states \ ^ x ), \^y)- There exists a measurement that 
correctly determines which of the two states we are given with error probability at most e if and 
only if\($ x \ifr y )\ < e', where e' = 2y/e(l - e). 

Since a unitary operator is just a change of basis, it does not change the inner product between 
any two quantum states, and thus the inner product can only change as a consequence of queries 
to the oracle. 

4 Adversary lower bounds 

Adversary lower bounds are of information theoretical nature. A basic idea in adversary lower 
bounds is to upper-bound the amount of information that can be learned in a single query. If little 
information can be learned in any one query, then many queries are required. We use spectral 
properties of T to put an upper bound on the amount of information the algorithm learns about the 
oracle. 

Let A be some quantum algorithm that computes some function F with bounded two-sided 
error. For every integer t > and every oracle x, let 

|^*> = U t O ie ..-U 1 O x Uo|0> (6) 

denote the quantum state after t queries to the oracle. To measure the progress of the algorithm, 
we define similarly to IIAmb02l [HNSTHl IB5D31 IBSS03II a weight function 

W^ = ^r[x,y]4V<^>, (V) 

where 5 is a fixed principal eigenvector of T, i.e., a normalized eigenvector corresponding to the 
largest eigenvalue of T, and where 5 X denotes the x th entry of 5. 

The algorithm starts in a quantum state |^°) = Uo|0) which is independent of the oracle x, and 
thus the total initial weight is 

w° = Y, r [x>vWv = Kr), (8) 

x,y 

where A(T) denotes the spectral norm of Y. The final state of the algorithm after T queries is j^J) 
if the oracle is x, and it is \ipy) if the oracle is y. If F(x) ^ F(y), we must have that | (0j \ipy) | < e' 
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by Fact[H and hence W T < e'W°. If the total weight can decrease by at most A by each query, 
the algorithm requires fi(^r) queries to the oracle. 

Following Barnum, Saks, and Szegedy [BSS03|, we upper bound A by the largest spectral 
norm of the matrices Tj, defined by 



T[x,y] if Xi^yi 
if Xi = yu 



(9) 



for each 1 < % < n. The theorem of [BSS03] is here stated (and proved) in a slightly more 
general form than in [BSS03] so that it also applies to non-boolean functions. Our proof aims at 
emphasizing distinguishability and differs from the original. 



Theorem 2 (Spectral method 

{0,1}^ -> {0,l} m , 



ma™ 



) For any adversary matrix V for any function F 

A(r) 



Q 2 (F) = n( 



do) 

maxj A(l i 

— W t+1 by the t + 1 st query is upper-bounded by 



Proof We prove that the drop in total weight W l 
the largest eigenvalue of the matrices IV 

For each < % < N, let Pj = J2 z >o z ) z \ denote the projection onto the subspace querying 
the 2 th oracle bit. Let (3 x> i = \Pi\ipD\ denote the absolute value of the amplitude of querying the 
i bit in the t + 1 st query, provided the oracle is x. Note that £-L #M = 1 for 

any oracle x, 

since the algorithm queries one of the N bits xi, . . . ,xn, or simulates a non-query by querying 
the oracle with i = 0. The t + 1 st query changes the inner product by at most the overlap between 
the projections of the two states onto the subspace that corresponds to indices i on which x» and yi 
differ, 



<«>-<^ +1 W +1 > 



The bigger the amplitudes of querying the bits i on which X{ and yi differ, the larger the drop in 
the inner product can be. 

Define an auxiliary vector a, [x] = 8 x /3 Xti and note that 



N 

E 

i=0 



N 

i=0 x 



A' 



5 lY^ = Y 5 * = l - 



i=0 
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The drop in the total weight is upper-bounded by 



\v\r-w 



t+i\ 



x,y 



= |2^ J2 n^y]SJyMPi\lpy) 

< 2^2^2Vi[x, y]8 x Sy ■ p x>i Pi 



x,y t 



< 



2 a*Tiai 

i 

2j]A(r,)H 2 

i 

< 2maxA(Tj)-\ |aj| 2 

i ' ^ 

i 

= 2maxA(Tj). 

i 

Here a* denotes the transpose of aj. The first inequality bounds the drop in inner product for a 
specific pair and follows from Equation[TT] The second inequality follows from the spectral norm 
of T. The second and third inequalities state that the best possible query distributes the amplitude 
of the query according to the largest principal eigenvector of the query matrices IV □ 



Example: Ordered Seaching 2 Returning to our example of ordered searching, for N 
adversary matrix with respect to the ordered basis (0001, 0011, 0111, 1111) is given by 



4, the 



s search (4) 



1 i 



1 1 





1 



The spectral norm is easily seen to be lower-bounded by the sum of the entries in the first row, 
A(r search( ' 4 ' ) ) > 1 + | + |. In general, ,X(r search ) is lower-bounded by the harmonic number Hjy-i, 
which is at least ln(iV). The spectral norm of the query matrices A(rf arch ) is maximized when 
i = \_N/ 2j , in which case it is upper-bounded by the spectral norm of the infinite Hilbert matrix 



[l/(r + s — l)]r,s>i» which is ir. We thus reprove the lower bound of 
searching given in [HNS02 ]. 



J\ ln(AT) 



for ordered 



5 Applying the spectral method 

The spectral method is very appealing in that it has a simple formulation, a basic proof, and gives 
good lower bounds for many problems. Spalek and Szegedy [ SS05 1 show that for any problem, 
the best lower bound achievable by the spectral method is always at least as good as the best 
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lower bound achievable by any of the previously published adversary methods. Their proof is 
constructive and illuminating: given any lower bound in any of the previously published adversary 
methods, they construct an adversary matrix T and prove it achieves the same lower bound. 

The first general quantum lower bound using adversary arguments was introduced by Ambainis 
in HAmb02l . As shown in HSS05L it can be derived from the spectral method by applying simple 
bounds on the spectral norm of T and each IY By definition, the numerator A(T) is lower-bounded 
by pa d*Td for any non-negative vector d, and by Mathias' lemma [Mat90|, the denominator A(I\) 
is upper-bounded by the product of a row-norm and a column-norm. 

Lemma 3 ( llMat90llSS05l ) Let G be any non-negative symmetric matrix and M, N non-negative 
matrices such that G = M o N is the entrywise product of M and N. Then 



where r x (M) is the £ 2 -norm of the x th row in M, and c y (N) is the £ 2 -norm of the y th column in N. 

Applying these two bounds, we obtain Ambainis' lower bound in [Amb02|. We refer to the 
method as an unweighted adversary method since it considers only two types of inputs: easy inputs 
and hard inputs. We construct a zero-one valued adversary matrix Y that corresponds to a uniform 
distribution over the hard input pairs. 

Theorem 4 (Unweighted method HAmb02l ) Let F be a partial boolean function, and let A C 
.F _1 (0) and B C be subsets of (hard) inputs. Let R C A x B be a relation, and set 

Ri = {(x,y) E R : Xi 7^ yi} for each 1 < % <n. Let m, m' denote the minimal number of ones in 
any row and any column in relation R, respectively, and let £, £' denote the maximal number of ones 
in any row and any column in any of the relations Ri, respectively. Then Q 2 (f) = £l(y/mm' /££'). 

Proof Let S — {(x, y) : (x,y) E i? V (y,x) E R} be a symmetrized version of R. Define a 
column vector d from the relation S by setting d x = \J\{y : (x, y) E S}\, and an adversary matrix 
r by setting T[x, y] = if and only if (x, y) E S. Then A(r) > j^d*Td = 1. For each of the 

matrices Tj, we apply Lemma[3]with M[x, y] = N[y, x] — 4- if and only if (x, y) E S. For every 



(x,y) E R, r x (M) < ^j£jd? x < ^/JJm and c y (N) < ^£'/d? y < y/l'/rri. For every (x,y) E 
S — R, the two inequalities are swapped. By Lemma|3l A(Tj) < m&x x jy: r t [x ,y]>o r x(M)c y (N) < 



The unweighted adversary method is very simple to apply as it requires only to spec- 
ify a set R of hard input pairs. It gives tight lower bounds for many computational prob- 
lems, including inverting a permutation [Amb02|, computing any symmetric function and count- 
ing IINW991 IBC+99I IBH+02I . constant-level and-or trees llAmb0 2 HM W031 . and various graph 
problems [DH + 04|. For some computational problems, the hardness does however not necessarily 
rely only on a few selected hard instances, but rather on more global properties of the inputs. Ap- 
plying the unweighted method on ordered searching would for instance only yield a lower bound 
of a constant. In these cases, we may apply the following weighted variant of the method, due to 
Ambainis HAmb()3l and Zhang HZha()4l . 



X(G) < max r x (M) c y (N), 




□ 
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Theorem 5 (Weighted method IAmb03l lZha04ID Let F : S — > {0,l} m be a partial function. 
Let w, w' denote a weight scheme as follows: 

• Every pair (x,y) G S 2 is assigned a non-negative weight w(x,y) = w(y,x) that satisfies 
w(x, y) = whenever F(x) = F(y). 

• Every triple (x, y, i) G S 2 x [N] is assigned a non-negative weight w'(x, y, i) that satisfies 
w'(x, y, i) — whenever Xi = yi or F(x) = F(y), and w'(x, y, i)w'(y, x, i) > w 2 (x, y) for 
all x, y, i with Xi ^ y^ 

Then 



Q 2 (F)=n\ min 

x,y,i 
w(x ,y) >0 



wt(x)wt(y) 
v(x,i)v(y,i) 



where wt(x) = J2 y w(x, y) and v(x, i) = J2 y w'(x, y, i) for all x G S and i G [N]. 

At first glance, the weighted method may look rather complicated, both in its formulation and 
use, though it is not. We first assign weights to pairs (x, y) of inputs for which F(x) ^ F(y), as in 
the spectral method. We require the weights to be symmetric so that they represent the difficulty 
in distinguishing between x and y. 

We then afterwards assign weights w'(x, y, i) that represent the difficulty in distinguishing x 
from y by querying index i. The harder it is to distinguish x from y by index i, compared to 
distinguishing y from x by index i, the more weight we put on (x, y, i) and the less on (y, x, i), and 
vice versa. 

To quantify this, define t(x, y, i) = w'(x, y, i)/w'(y, x, i). Then t(x, y, i) represents the relative 
amount of information we learn about input pairs (x, z) compared to the amount of information 
we learn about input pairs (u,y), by querying index i. If we, by querying index i, learn little 
about x compared to y, we let t(x,y,i) be large, and otherwise small. Consider we query an 
index i for which Xi ^ yi. Then we learn whether the oracle is x or y. However, at the same 
time, we also learn whether the oracle is x or z for any other pair (x, z) for which Xi ^ Z{ and 
F(x) 7^ F(z); and similarly, we learn whether the oracle is u or y for any other pair (u, y) for 
which m 7^ y-i and F{u) ^ F(y). The less information querying index i provides about pairs 
(x, z) compared to pairs (u, y), the larger we choose t(x, y, i). Having thus chosen t(x, y, i), we 
set w'(x, y, i) = w(x, y) ^t(x } y } i) and w'(y, x, i) = w(x, y)/ yjt(x,y,i). 

We show next that the weighted method yields a lower bound of fi(logiV) for the ordered 
searching problem. This proves that the weighted method is strictly stronger than the unweighted 
method. The weighted method yields strong lower bounds for read-once formula [BS04| and it- 
erated functions [Amb03|. Aaronson [Aar04|, Santha and Szegedy [SS04|, and Zhang [Zha05| 
use adversary arguments to prove lower bounds for local search, a distributed version of Grover's 
problem. Spalek and Szegedy prove in [SS05] that the weighted method is equivalent to the spec- 



tral method — any lower bound that can be achieved by one of the two methods can also be shown 
by the other. Their proof is constructive and gives simple expressions for converting one into the 
other. The main weights w(x, y) are the coefficients of the weight function W l for the input pair 
(x, y), that is, w(x, y) = T[x, y]5 x 8 y , and the secondary weights w'(x, y, i) follow from Mathias' 
lemma [Mat90| (Lemma 01). 
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Example: Ordered Seaching 3 To apply the weighted method on ordered searching, we pick the 
same weights w(x, y) = T search [x, y] S x S y as in the spectral method as there are no strong reasons 
for choosing otherwise. Now, consider t(x,y,i) with F(x) < i < F(y) so that Xi ^ y^. By 
querying index i, we also learn to distinguish between x and z for each of the F(y) — i inputs z 
with i < F(z) < F(y), and we learn to distinguish between u and yfor each of the i — F{x) + 1 
inputs u with F(x) < F{u) < i. We thus choose to set 

, ( . \F{x)-i\+l 
t(x,y,i) - 



\F(y)-i\ + l 



Plugging these values into the weighted method yields a lower bound offl(\ogN) for ordered 
searching. 



6 Limitations of the spectral method 

The spectral method and the weighted adversary method bound the amount of information that can 
be learned in any one query. They do not take into account that the amount of information that can 
be learned in the j th query might differ from the amount of information that can be learned in the 
k th query. 

In 1999, Zalka [Zal99] successfully managed to capture the amount of information that can 
be learned in each individual query for a restricted version of Grover's problem [Gro96|. In this 
restricted version, we are promised that the input oracle x is either the zero-string (so |x| = 0) 
or exactly one entry in x is one (so |x| = 1), and the goal is to determine which is the case. By 
symmetry considerations, Zalka demonstrates that Grover's algorithm saturates some improved 
inequalities (which are similar to Eq.fTTI) and hence is optimal, even to within an additive constant. 

Since current adversary methods do not capture the amount of information the algorithm cur- 
rently knows, we may simply assume that the algorithm already knows every bit of the oracle and 
that it tries to prove so. This motivates a study of the relationship between the best bound achiev- 
able by the spectral method and the certificate complexity. A certificate for an input x E {0, 1}^, 
is a subset C C [N] of input bits such that for any other input y in the domain of F that may be ob- 
tained from x by flipping some of the indices not in C, we have that F(x) = F(y). The certificate 
complexity C X (F) of input x is the size of a smallest certificate for x. The certificate complexity 
C(F) of a function F is the maximum certificate complexity of any of its inputs. We also define 
the ^-certificate complexity C Z (F) when taking the maximum only over inputs that map to z. The 
spectral theorem can then never yield a lower bound better than a quantity that can be expressed in 
terms of certificate complexity. 

Lemma 6 aLM04l lZha(>4llsS05h Let F : S -> {0,1} be any partial boolean function. The 
spectral adversary lower bound Adv(F) is at most min { ^Cq(F)N, a/Ci(F)A^}. If F is total, 
the method is limited by y / Co(F)C\(F). 

The certificate complexity of a function F : {0,1}^ — ■> {0,l} m is itself polynomially related 
to the block sensitivity of the function. An input x E {0, 1}^ is sensitive to a block B C [N] 
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if F(x) 7^ F(x B ), where x B denotes the input obtained by flipping the bits in x with indices 
from B. The block sensitivity bs x (F) of input x is the maximum number of disjoint blocks 
Bi, B 2 , . . . , Bk C [N] on which x is sensitive. The block sensitivity bs(F) of F is the maxi- 
mum block sensitivity of any of its inputs. We also define the ,2-block sensitivity bs 2 (F) when 
taking the maximum only over inputs that map to z. 

For any boolean function F : {0, 1}^ — ► {0, 1}, the certificate complexity is upper-bounded 
by C(F) < bs (-F)bsi(F), and thus so is the spectral adversary method. Conversely, Adv(F) > 
y^bs(F) by a zero-one valued adversary matrix T: Let x' G {0, 1}^ be an input that achieves the 
block sensitivity of F, and let Bi, B 2 , . . . , B k C [N] be disjoint blocks on which x' is sensitive, 
where k = bs(F). Set T(F)[x,x B ] = 1 if and only if x = x' and B is one of the k blocks Bi and 
close T under transposition. Then A(T) = \fk and maxj A(r») = I, and thus 



v / bs(F) < Adv(F) < bs (F)bsi(F). (12) 

The spectral adversary method is not suitable for proving lower bounds for problems related to 
property testing. If function F : S — > {0, 1} is a partial function with S C {0, 1}^ such that every 
zero-input is of Hamming distance at least en from every one-input, then the spectral theorem does 
not yield a lower bound better than 1/e. 

Laplante and Magniez introduce in |LM04| a lower-bound method based on Kolmogorov com- 
plexity. They show by direct constructions that their method is at least as strong as each of th e two 



methods, the spectral and weighted adversary method. Spalek and Szegedy then show in [SS05 1 
that the spectral method is at least as strong as the Kolmogorov complexity method, allowing 
us to conclude that the three methods are equivalent. Having such a variety of representations 
of the same method shows that the adversary method is very versatile and captures fundamental 
properties of functions. Indeed, Laplante, Lee, and Szegedy [LLS05| show that the square of the 
adversary bound is a lower bound on the formula size. The following lower-bound method is a 
combinatorial version of the Kolmogorov complexity method. 

Theorem 7 (Minimax method |LM04, SS05|) Let F : S —> {0, l} m be a partial function and 
A a bounded-error quantum algorithm for F. Let p : S x [N] — > be a set of\S\ probability 
distributions such that p x (i) denotes the average probability of querying the i th input bit on input 
x, where the average is taken over the whole computation of A. Then the query complexity Qa of 
algorithm A satisfies 

1 

Qa > M p = max 



x,y:F(x)^F(y) \' l>A>) I'.Jj) 

The previous methods satisfy the property that if we plug in some matrix or relation, we get 
a valid lower bound. The minimax method is principally different. A lower bound computed by 
the minimax theorem holds for one particular algorithm A, and it may not hold for some other and 
better algorithm. However, we may obtain a universal lower bound that holds for every bounded 
error algorithm by simply taking the minimum of the bound M p over all possible sets of probability 
distributions p. The spectral bound and the minimax bound are in a primal-dual relation: the best 
lower bound that can be obtained by any adversary matrix T equals the smallest bound that can 
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JU I 

be obtained by a set of probability distributions p [ SS05 1 . Primal methods are used for obtaining 
concrete lower bounds and dual methods are used for proving limitations of the method, as in 
Lemma 

A useful property of the adversary method is that it composes. Consider a function of the form 
H = F o (d, . . . , G k ), where F : {0, l} k -> {0, 1} and d : {0, 1}^ {0, 1} for i = 1, . . . , k 
are partial boolean functions. A composition theorem states the complexity of function H in terms 
of the complexities of F and G\, . . . , Gk- Barnum and Saks [BS04| use composition properties 
to prove a query lower bound of Vt(\fN) for any read-once formula, Ambainis | Amb03 1 proves a 
composition lower bound for iterated boolean functions, and Laplante, Lee, and Szegedy [LLS05 1 
prove a limitation on composition lower bounds for functions G{ for which the adversary bound 
is upper bounded by a common bound b. To formulate a composition theorem for arbitrary cases 
when the functions Gi may have different adversary bounds, we require a weighted version of the 
spectral method. 

Let F : {0, 1}^ — * {0, 1} be a partial boolean function and a = (ai, . . . , ajv) a string of 



A(r) 

Adv a (F) = maxmin I ai 



positive reals. Let 

r i \ l X(Ti 

where T ranges over all adversary matrices for F. If the weights are all 1, then our new quantity 
Adv a (F) coincides with the spectral adversary bound and is thus a lower bound on the quantum 
query complexity of F. If the weights a are non-uniform, then Adv Q (F) is a new abstract com- 
plexity measure that assigns cost to querying the i th input bit. We can then prove [HS05| that 
the quantity Adv a composes in the following sense. 



Theorem 8 (Composition Theorem llBg04l lAmhM ILLS051 IhS05 I) For any composite func- 



tion H = F o (Gi, . . . , G k ), where F : {0, l} k -> {0, 1} and G f : {0, 1}** -> {0, 1} are partial 
boolean functions, 

Adv a (H)=Adv l3 (F), 
where fa = Adv a i(Gj), and a = (a 1 , . . . , ot k ) is a k-tuple of strings a 1 G *. 

A natural generalization of Graver's problem is the so-called fc-fold search problem in which 
we are promised that exactly k entries of the input oracle x are one (so \x\ = k), and the goal 
is to find all of these k indices. We say an algorithm A succeeds if it outputs a subset S C [N] 
of size k and S contains all indices i E [N] for which Xi = 1. Thus, by definition, it fails even 
if it outputs all but one of the k indices. The fc-fold search problem can be solved in 0(y/kn) 
queries, esse ntially by sequentially running Graver's search algorithm k times. Klauck, Spalek, 
and de Wolf [KSW04| show that if the number of queries is less than e\fkn for some constant e, 
then the success probability of A is exponentially small in k. They thus prove a strong direct 
product theorem for the fc-fold search problem. One of the main elements of the proof is the 
polynomial method which we discuss in the next section. 

In very recent work, Ambainis [Am05a| proposes an exten sion of the adversary method and 
uses it to reprove the strong direct product theorem of Though the following very brief 



description of the proof does not do full justice to the method, we hope it conveys some of the 
intuition on which [ Am05a| is based. The algorithm runs on a uniform superposition of all inputs. 
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During the computation, the input register gets entangled with the workspace of the algorithm 
due to the queries to the oracle. We trace out the workspace and examine the eigenspaces of the 
density matrix of the input register. Due to symmetries, there are exactly k+1 eigenspaces, indexed 
by the number of ones the algorithm "knows" at that stage of the algorithm. In the beginning, all 
amplitude is in the th eigenspace. One query can only move little amplitude from the i th eigenspace 
to the i + 1 st eigenspace. If the algorithm has good success probability, the quantum amplitude in 
high eigenspaces must be significant, since the algorithm must "know" most of the k indices, which 
implies a lower bound on the query complexity. 

7 Polynomial lower bounds 

There are essentially two different methods known for proving lower bounds on quantum compu- 
tations. The historically first method is the adversary method we discuss above. It was introduced 
in 1994 by Bennett, Bernstein, Brassard, and Vazirani, and published in 1997 in the SIAM Journal 
on Computing, in a special section that contains some of the most outstanding papers on quan- 
tum computing. The second method was introduced shortly after, in 1998, by Beals, Buhrman, 
Cleve, Mosca, and de Wolf [BB + 01 1, and implicitly used by Fortnow and Rogers in [FR99|. Their 
approach is algebraic and follows earlier very successful work on classical lower bounds via poly- 
nomials (see for instance Beigel's 1993 survey [Bei93 1 and Regan's 1997 survey [Reg97]). We first 
establish that any partial boolean function F : S — > {0, 1}, where S C {0,1}^, can be represented 
by a real- valued polynomial p : — > -ft. 

Definition 9 Let F : S — > {0, 1} be a partial boolean function, where S C {0,1}^. An N- 
variable polynomial p represents F if p(x) = F{x) for all x E S, and it approximates F if 
\p(x) — F(x)\ < \for all x G S. The degree of F, denoted deg(F), is the minimal degree of a 
polynomial representing F. The approximate degree of F, denoted deg(F), is the minimal degree 
of a polynomial approximating F. 

The crux in IIBB+01I is in showing that any quantum algorithm A computing some function F 
gives rise to some polynomial p& that represents or approximates F. 

Theorem 10 ([BB + 01|) Let A be a quantum algorithm that computes a partial boolean func- 
tion F : S — > {0, 1}, where S C {0, 1}^, using at most T queries to the oracle 0' x . Then there 
exists an N-variate real-valued multilinear polynomial pa '■ —> 3? of degree at most IT, which 
equals the acceptance probability of k. 

Proof In this theorem, we use the oracle O^, which is equivalent to the oracle O^, since it allows 
for simple formulations. We first rewrite the action of as 

0' x \i,b;z) = (1 -Xi)\i,b;z) +x i |i,6© l;z) (13) 

where we define Xj = for i = so that we can simulate a non-query by querying Xi with % — 0. 
Suppose we apply O^, on some superposition ^2 ibz 0£ itbjZ \i, b; z) where each amplitude a itbiZ is an 
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iV-variate complex- valued polynomial in x of degree at most j. Then, by Eq.[J21 the resulting state 
Si b z Pi,b,z\h b; z) is a superposition where each amplitude (3i^, z is an iV-variate complex- valued 
polynomial in x of degree at most j + 1. By proof by induction, after T queries, each amplitude 
can be expressed as a complex-valued polynomial in x of degree at most T. The probability that 
the final measurement yields the outcome 1, corresponding to accepting the input, is obtained by 
summing some of the absolute values of the amplitudes squared. The square of any of the absolute 
amplitudes can be expressed as a real- valued polynomial p A in x of degree at most 2T. TheoremfTUI 
follows. □ 

The above theorem states that to any quantum algorithm A computing a boolean function F : 
S — > {0, 1}, where S C {0, 1}^, we can associate an iV-variate polynomial p& : $t N — > 3? that 
expresses the acceptance probability of the algorithm on any given input. If algorithm A is exact, 
i.e., if A always stops and outputs the correct answer, then p&(x) = F(x) for all x E S, and thus 
Pa represents F. If A has bounded error, then < Pa(x) < 1/3 if F(x) = and 2/3 < Pa(x) < 1 
if F(x) = 1, and thus p A approximates F. The degree of p/\ is at most twice the number of queries 
used by algorithm A. Consequently, the degree of a function is a lower bound on the quantum 
query complexity, up to a factor of two. 

Corollary 11 (Polynomial method BBB + 01l ) For any partial boolean function F : S — > {0, 1}, 

where S C {0, 1}*, we have Q E (F) > deg(F)/2 and Q 2 (F) > deg(F)/2. 



8 Applying the polynomial method 

The challenge in applying the polynomial method lies in the dimensionality of the input. Typically, 
the method is applied by first identifying a univariate or bivariate polynomial that captures essential 
properties of the problem, and then proving a lower bound on the degree of that polynomial. 
The second part is typically reasonably straightforward since polynomials have been studied for 
centuries and much is known about their degrees. The possibly simplest nontrivial example is 
when F is the threshold function Thr t defined by Thr t (x) = 1 if and only if \x\ > t. It is easy 
to see that deg(Thr f ) = Q(N) for all nontrivial threshold functions, and thus Q E (T\r\r t ) = Cl(N). 
Paturi HPat92l shows that deg(Thr f ) = Q(y/(t + l)(N -t + 1)), and we thus readily get that 
Q 2 (Thrt) = n(y/(t+ 1)(N -t + 1)), which is tight by quantum counting llBH+021 IrB+oTI 
This degree argument extends to any symmetric function F by writing F as a sum of threshold 
functions. The same tight lower bounds for symmetric functions can also be obtained by the 
unweighted adversary method (see the paragraph after Theorem |4j). 

For general non-symmetric functions, the polynomial method is, however, significantly harder 
to apply. For problems that are "close" to being symmetric, we can sometimes succeed in con- 
structing a univariate or bivariate polynomial that yields a non-trivial lower bound. The first and, 
in our view, most important such a result was obtained by Aaronson in [ Aar02] in which he proves 
a lower bound of Vt{N 1 ^) on any bounded-error quantum algorithm for the collision problem. 

The collision problem is a non-boolean promise problem. The oracle is an A^-tuple of positive 
integers between 1 and M, which we think of as a function X : [N] — > [M] . We model the oracle 
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0^ so that a query to the i th entry of the oracle returns the integer X(i). Specifically, 0" x takes as 
input \i, r; z) and outputs \i, r®X(i); z) where < r < 2 m for m = |~log 2 (M + 1)] , and r®X(i) 
denotes bitwise addition modulo 2. We are promised that either X is a one-to-one function, or X 
is two-to-one, and the goal is to determine which is the case. 

The result of Aaronson was shortly after improved by Shi [Shi02| to fi(iV 1//4 ) for general 
functions X : [N] — > [M], and to ^(iV 1 / 3 ) in the case the range is larger than the domain by a 
constant factor, M > |iV. The lower bounds of Aaronson and Shi appears as a joint article [AS04]. 
Finally, Kutin [Kut05J and Ambainis [Am05b| independently found remedies for the technical 
limitations in Shi's proof, yielding an ^(iV 1 / 3 ) lower bound for all functions, which is tight by an 
algorithm that uses Grover search on subsets by Brassard, H0yer, and Tapp IBH M97I . 

The best lower bound for the collision problem that can be obtained using the adversary method 
is only a constant, since any one-to-one function is of large Hamming distance to any two-to-one 
function. Koiran, Nesme, and Portier [ KNP05 1 use the polynomial method to prove a lower bound 
of fi(logiV) for Simon's problem [Sim97|, which is tight [Sim97, BH97|. Simon's problem is a 
partial boolean function having properties related to finite abelian groups. Also for this problem, 
the best lower bound that can be obtained using the adversary method is a constant. 

In contrast, for any total boolean function F : {0,1}^ — > {0,1}, the adversary and polynomial 
method are both polynomially related to block sensitivity, 



It follows from IB B+011 that deg(F) < bs 3 (F), and from Nisan and Szegedy HNS92I that 
6deg(F) 2 > bs(F). Buhrman and de Wolf [BW02] provide an excellent survey of these and 
other complexity measures of boolean functions. 

The polynomial lower bound is known to be inferior to the weighted adversary method for 
some total boolean functions. In HAmb0 3l. Ambainis gives a boolean function F : {0, l} 4 — > 
{0, 1} on four bits, which can be described as "the four input bits are sorted" ILLS05I . 
for which deg(F) = 2 and for which there exists an adversary matrix Y F satisfying that 
A(r F )/ maxj A(rf) = 2.5. We compose the function with itself and obtain a boolean function 
F 2 = F o (F, F, F, F) : {0, l} 16 -> {0, 1} defined on 16 bits for which deg(F 2 ) = 4, and for 
which A(r F2 )/ maxj A(Tf 2 ) = 2.5 2 , by the composition theorem. Iterating n times, yields a func- 
tion F on N = 4™ bits of degree deg(F) = 2 n , with spectral lower bound 2.5™ = deg(F) 1 " 32 *", by 
the composition theorem. The thus constructed function F is an example of an iterated function 
of low degree and high quantum query complexity. It is the currently biggest known gap between 
the polynomial method and the adversary method for a total function. Another iterated total func- 
tion for which the adversary methods yield a lower bound better than the degree, is the function 
described by "all three input bits are equal" [ Amb03 1. 

The polynomial method is very suitable when considering quantum algorithms computing 
functions with error e that is sub-constant, whereas the adversary method is not formulated so 
as to capture such a fine-grained analysis. Buhrman, Cleve, de Wolf, and Zalka [BC + 99| show that 
any quantum algorithm for Grover' s problem that succeeds in finding an index i for which Xi = 1 
with probability at least 1 — e, provided one exists, requires fi(yW log(l/e)) queries to the oracle, 



y/bs(F)/6 < deg(F) < deg(F) < bs 3 (F) 



(14) 
(15) 



v / bs(F) < Adv(F) < bs 2 (F). 
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which is tight. A possibly more familiar example is that any polynomial approximating the parity 
function with any positive bias e > (as opposed to bias ~ where I = | — \) has degree N, since 
any such polynomial gives rise to a univariate polynomial of no larger degree with N roots. Hence, 
any quantum algorithm computing the parity function with arbitrary small bias e > requires N/2 
queries to the oracle, which is tight. 

A useful property of representing polynomials is that they compose. If p is a polynomial 
representing a function F, and polynomials qx, q 2 , . . . , q k represent functions Gi, . . . , G k , then 
p o (g x , . . . , q k ) represents F o (G\, . . . , Gk), when well-defined. This composition property does 
not hold for approximating polynomials: if each sub-polynomial qi takes the value 0.8, say, then 
we cannot say much about the value p(0.8, . . . , 0.8) since the value of p on non-integral inputs 
is not restricted by the definition of being an approximating polynomial. To achieve composition 
properties, we require that the polynomials are insensitive to small variations of the input bits. 
Buhrman, Newman, Rohrig, and de Wolf give in [BN + 05| a definition of such polynomials, and 
refer to them as being robust. 

Definition 12 (Robust polynomials BBN + 05l ) An approximate N-variate polynomial p is robust 
on S C {0,1}^ if\p(y) —p(x)\ < I for every x G S and y G 9R M such that \yi — Xi\ < I for every 
i = 1, . . . , M. The robust degree of a boolean function F : S — > {0, 1}, denoted rdeg(F), is the 
minimal degree of a robust polynomial approximating F. 

Robust polynomials compose by definition. Buhrman et al. llBN + 05l show that the robust de- 
gree of any total function F : {0, 1} N — > {0, 1} is O(N) by giving a classical algorithm that uses a 
quantum subroutine for Grover's problem !Gro96l which is tolerant to errors, due to H0yer, Mosca, 
and de Wolf IIHMW03I . Buhrman et al. HBN+051 also show that rdeg(F) G 0(deg(F) logdeg(F)) 
by giving a construction for turning any approximating polynomial into a robust polynomial at the 
cost of at most a logarithmic factor in the degree of F. This implies that for any composite function 
H = F o (G, . . . , G), we have deg(H) G 0(deg(F)deg(G) logdeg(F)). It is not known whether 
this is tight. Neither is it known if the approximate degree of H can be significantly smaller than the 
product of the approximate degrees of F and G. The only known lower bound on the approximate 
degree of H is the trivial bound fi(deg(F) + deg(G)). 

An and-or tree of depth two is a composed function F o (G, . . . , G) in which the outer function 
F is the logical AND of VN bits, and the inner function G is the logical OR of \fN bits. By 
the unweighted adversary method, computing and-or trees of depth two requires VL(\fN) queries. 
H0yer, Mosca, and de Wolf [HMW03| give a bounded-error quantum algorithm that uses 0(\/N) 
queries, which thus is tight. The existence of that algorithm implies that there exists an approxi- 
mating polynomial for and-or tree of depth two of degree 0(VN). No other characterization of 
an approximating polynomial for and-or trees of depth two of degree 0(\/N) is currently known. 
The best known lower bound on the approximate degree of and-or trees of depth two is ^(iV 1 / 3 ), 
up to logarithmic factors in N, by a folklore reduction from the element distinctness problem on 
VN integers IAS04I . 
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9 Concluding remarks 



We have been focusing on two methods for proving lower bounds on quantum query complexity: 
the adversary method and the polynomial method. Adversary lower bounds are in general easy to 
compute, but are limited by the certificate complexity. Known lower bounds are constructed by 
identifying hard input pairs, finding weights accordingly, and computing either the spectral norm 
of some matrices, or applying the weighted method. Polynomial lower bounds may yield stronger 
bounds, but are hard to prove. Known lower bounds by the polynomial methods are constructed by 
identifying symmetries within the problem, reducing the number of input variables to one or two, 
and proving a lower bound on the degree of the reduced polynomial. 

Barnum, Saks, and Szegedy give in [BS S03I a third lower bound method that exactly charac- 
terizes the quantum query complexity, but this strength turns out also to be its weakness: it is very 
hard to apply and every known lower bound obtained by the method can also be shown by one of 
the other two methods. In a very recent work, Ambainis [Am05a| extends the adversar y method 
and uses it to reprove a strong direct product theorem by Klauck, Spalek, an d de Wol f | KSW04 1 
obtained by techniques that include the polynomial method. Klauck et al. IKS W04I show that 
their strong direct product theorem implies good quantum time-space tradeoffs, including a quan- 
tum lower bound of T 2 • S = Q(N 3 ) for sorting. A significant body of work have been conducted 
on lower bounds on communication complexity. We refer to de Wolf's excellent survey [Wol02| 
as a possible starting point. 

There is a range of problems for which we do not currently know tight quantum query bounds. 
One important example is binary and-or trees of logarithmic depth. A binary and-or tree on N = 4™ 
variables is obtained by iterating the function F(xi, X2, x$, X4) = (x\ A x%) V (£3 A £4) in total 
n times. The classical query complexity for probabilistic algorithms is 6(iV a753 ) [SW86, Sni85, 
San95|. No better bounded-error quantum algorithm is known. The best known lower bound on 
the quantum query complexity is £l(y/~N) by embedding the parity function on y/N bits and noting 
that the parity function has linear query complexity, which can be shown by either method. 

Magniez, Santha, and Szegedy give in [MSS05 1 a quantum algorithm for determining if a graph 
on N vertices contains a triangle which uses 0(N 1,3 ) queries to the adjacency matrix. The best 
known lower bound is Q,(N) by the unweighted adversary method, and has been conjectured not to 
be tight HAmb03l . The problem of triangle-identification is an example of a graph property, which 
is a set of graphs closed under isomorphism. Sun, Yao, and Zhang [SYZ04| show that there exists 
a non-trivial graph property of quantum query complexity 0(\/N), up to logarithmic factors in N. 

Gasarch, in a survey on private information retrieval, published in this Computational Com- 
plexity Column in the Bulletin [Gas04|, writes: "A field is interesting if it answers a fundamental 
question, or connects to other fields that are interesting, or uses techniques of interest." It is our 
hope that the reader will find that the surveyed area of quantum lower bounds fulfills each of those 
three criteria. 
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